CVE-2025-46806: Misaligned Memory Accesses in `is_openvpn_protocol()`

6.9 CVSS

Description

A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4.

Classification

CVE ID: CVE-2025-46806

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.9

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Problem Types

CWE-823: Use of Out-of-range Pointer Offset

Affected Products

Vendor: https://github.com/yrutschle/sslh/releases/tag/v2.2.4

Product: sslh

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 17.32% (scored less or equal to compared to others)

EPSS Date: 2025-06-08 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-46806
https://github.com/yrutschle/sslh/releases/tag/v2.2.4
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46806

Timeline